CVE-2016-7966: Debian Linux
High severity, CVSS 7.3. EPSS: 2.3% chance of exploitation in the next 30 days.
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.
Affected products
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 25 only
- Kde Kmail: up to and including 4.4.0
- Suse Linux Enterprise: version 12.0 only
Published 2016-12-23. Last modified 2026-06-17.